
Poland integrates MyDr medical breach data into national portal for 19 million citizens
Polish authorities updated the government portal bezpiecznedane.gov.pl on 29 August 2026, allowing citizens to check whether their personal identification numbers were compromised across 12,000 healthcare providers.
Government verification portal rollout
On 29 August 2026, the Polish government updated its verification portal at bezpiecznedane.gov.pl to include information from the data breach at medical software company MyDr. The breach compromised personal details belonging to 19 million Polish citizens across 12,000 public and private healthcare facilities. Heavy user traffic following the update forced the system to place visitors in a virtual queue to manage server capacity. Users can access the platform free of charge by authenticating through the mObywatel application, electronic banking, an electronic ID card, or a trusted profile.
The system allows individuals to check whether their national identification number (PESEL), telephone number, or email address appeared in the compromised databases. Polish security services confirmed that while an unauthorized party breached MyDr systems, authorities have not found evidence that the stolen files were publicly released online.
Scope of disclosed information
The government portal only provides binary confirmation of whether an individual's personal identifiers were part of the breach. It does not store medical records, prescription histories, or visit notes. Patients seeking details regarding the specific medical records affected must contact their individual medical practices or clinics directly. Head of the Personal Data Protection Office Mirosław Wróblewski explained the legal constraints governing the state verification tool.
The statutory provisions clearly determine which categories of data may be processed on the Bezpieczne Dane portal. The state, specifically CSIRT NASK, which manages this system, cannot demand any information from administrators or processing entities regarding medical histories, medical procedures, or patient prescriptions. There will only be ordinary, basic data that allows citizens to identify themselves and determine whether the breach affects them: surname, date of birth, residential address, sex, place of birth, telephone number, and PESEL number. This is the minimum set of information that enables verification on a simple yes-or-no basis: your data leaked or did not leak.
Chronology and system access
The security incident originated in early August 2026 when unauthorized actors infiltrated the electronic health records system operated by MyDr. The perpetrators attempted contact with the company on 5 August, but after receiving no response, they disclosed data to the cybersecurity portal Zaufana Trzecia Strona on 10 August. The Ministry of Digital Affairs publicly confirmed the breach on 12 August, directing citizens to take preventative security steps while technical teams and police prepared the verification registry.
- Hackers attempt contact with MyDr following unauthorized database access
- Security website Zaufana Trzecia Strona discloses the system intrusion
- Minister of Digital Affairs publicly confirms the data breach
- Government integrates breach data into the national verification portal
Investigations and security guidance
The Central Cybercrime Bureau is conducting a criminal investigation under the supervision of the Warsaw District Prosecutor's Office. The inquiry focuses on unauthorized access to the IT system and unlawful data transmission, offenses carrying a maximum penalty of three years in prison. The Personal Data Protection Office opened an administrative inspection into MyDr to evaluate the company's technical measures, organizational controls, and risk analysis procedures.
Deputy Minister of Digital Affairs Dariusz Standerski announced plans for legislative reforms to increase statutory liabilities for organizations processing medical data. Deputy Minister Michał Gramatyka defended the timeline of the portal launch against public criticism regarding delays, pointing to necessary coordination with law enforcement. The Ministry of Health and cybersecurity agencies recommend that citizens freeze their PESEL numbers using mObywatel or the gov.pl website to prevent unauthorized financial commitments, activate multi-factor authentication, and monitor for suspicious phone calls or phishing attempts.


